Threat Detection and Incident Response must be evaluated in the context of the organization ' s business model, operating environment, assets, adversaries, and industry-specific threat landscape . Detection engineering cannot be prioritized effectively using technical indicators alone.
For example, credential-access activity affecting an ordinary laboratory workstation and the same activity affecting a privileged financial system may require substantially different priorities. Similarly, a healthcare organization, financial institution, manufacturer, and cloud provider have different critical systems, regulatory requirements, attack surfaces, and likely adversary objectives.
MITRE ATT & CK provides an excellent taxonomy for adversary tactics and techniques, but ATT & CK itself does not define an organization ' s risk appetite . Risk appetite depends on business governance and tolerance for operational, financial, regulatory, and security impact. Therefore, option B improperly substitutes a threat-behavior framework for a business risk-management decision.
Focusing on the least impactful threat vectors is equally inconsistent with risk-based security engineering. Effective programs allocate detection and response resources according to realistic threats and organizational consequences.
The question appears in the lifecycle section on page 3 of the supplied material.
Study Guide topics: Threat Detection and Incident Response lifecycle, business context, risk prioritization, threat modeling, MITRE ATT & CK, program maturity.